CVE-2026-41163 Details
Description
bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "overlay mount" operation, allowing the creation of overlay mounts which is otherwise not allowed in the setuid version of bubblewrap. This issue has been patched in version 0.11.2.
A privilege escalation vulnerability has been identified in Bubblewrap versions 0.11.0 prior to 0.11.2, when installed in setuid mode. This vulnerability allows users to use ptrace to attach to Bubblewrap and manipulate the unprivileged part of the sandbox setup phase. As a result, attackers can arbitrarily execute privileged operations, particularly the 'overlay mount' operation, which is otherwise restricted in the setuid version of Bubblewrap. The issue has been patched in version 0.11.2.
Users should update to Bubblewrap version 0.11.2. Those using setuid mode should transition to a non-setuid version of Bubblewrap, as support for setuid will be removed in future releases.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 9, 2026CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-41163 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2468439 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41163.json | redhat-SADP | |
| https://github.com/containers/bubblewrap/releases/tag/v0.11.2 | [email protected] | Release NotesVendor |
| https://github.com/containers/bubblewrap/security/advisories/GHSA-xq78-7hw4-5jvp | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | redhat-SADP |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bubblewrap | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 9, 2026 | New CVE Received | [email protected] |
Volerion